starcitizenwiki/embedvideo is vulnerable to Missing Authorization
65
Medium Risk
Special:RefreshEmbedVideoMetadata declares the embedvideo-refreshmetadata right but never checks it at request time, so any visitor who can reach the page, including anonymous users on a public wiki, can trigger a metadata refresh on a local audio or video file. The special page overrides execute() and calls neither parent::execute() nor checkPermissions()/authorizeAction(), and no other code in the request path performs a permission check. Hiding the action tab in EmbedVideoHooks only removes the UI link; the page's canonical name and URL remain publicly reachable. The fix adds a getRestriction() lookup and calls checkPermissions() before the special page processes a refresh request.
You are affected if you are using a version that falls within the vulnerable range.
starcitizenwiki/embedvideo is vulnerable to Missing Authorization in versions 4.1.0 - 4.1.0.
Upgrade the starcitizenwiki/embedvideo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.